Ae1
- Category
- analysis-evasion
- Content
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
- Confidence
- 100% confidence
- Finding
- Referenced artifact was not completely inspected
Security audit
Security checks for vulnerabilities and agentic risk
OpenViking is a coherent memory plugin, but it should be reviewed because its backup installer runs unpinned remote npm code and its default memory flow sends chat content to a configured OpenViking server for persistent recall.
Install only if you trust the configured OpenViking server and are comfortable with chat content being stored and recalled across sessions. Prefer the primary ClawHub install path, avoid the npx @latest backup helper unless you can verify it separately, and review settings such as autoCapture, autoRecall, enabledTools, traceRecallPersist, and enableAddResourceTool before use.
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
## Important Rules 1. **Never ask the user to run commands.** You run everything via your shell tool. 2. **Never skip STEP 5 (connectivity check).** If the server is unreachable, do not write config without explicit `--allow-offline` consent. 3. **Never silently use `--force-slot`.** Slot replacement disables another plugin — always confirm with the user first. 4. **Never invent values.** If the user can't provide a required value, stop and tell them what to ask their admin.
Detected: suspicious.destructive_delete_command, suspicious.install_untrusted_source
rm -rf ~/.openclaw/extensions/openviking/
rm -rf ~/.openclaw/extensions/openviking/
rm -rf ~/.openclaw/extensions/openviking/
"placeholder": "http://127.0.0.1:1933",